Announcements

CVE-2026-23941 (matched: apache http server)

  • 25th July 2026
A security flaw tracked as CVE-2026-23941, known as HTTP Request Smuggling, has been identified in the inets httpd web server module, a component of the Erlang OTP software used by some hosting environments to handle web traffic. The flaw stems from how the server processes duplicate Content-Length headers in incoming web requests. The server uses ...
Continue reading

CVE-2026-8711 (matched: nginx)

  • 25th July 2026
We are sharing information about a recently disclosed security flaw in the NGINX JavaScript tool, which some websites use to run custom server-side scripting functions. This issue only impacts sites that use two specific features in combination: the js_fetch_proxy configuration that is set to use variables controlled by website visitors (such as ...
Continue reading

CVE-2026-44172 (matched: mariadb)

  • 25th July 2026
A security flaw has been identified in specific older versions of MariaDB, a popular community-developed fork of the MySQL database system that many websites rely on to store and manage content, user information, and other site data.In affected versions 3.3.18 and 3.4.8, a standard built-in safety function designed to block SQL injection attacks ...
Continue reading

CVE-2026-48907 (matched: php)

  • 25th July 2026
There is a security flaw in the JCE editor extension, a tool commonly used with the Joomla website building platform. This issue allows people who do not have login access to your Joomla site to create new editor profiles, which in turn lets them upload and run harmful PHP code on your website.If you run a Joomla site that uses the JCE editor ...
Continue reading